Bug#846298: tomcat7: Security update causes java.lang.ClassNotFoundException: org.apache.jasper.runtime.JspRuntimeLibrary$PrivilegedIntrospectHelper

2016-12-05 Thread Emmanuel Bourg
Hi Anthony, Thank you for reporting this issue. This was caused by the fix for CVE-2016-5018 in the version 7.0.56-3+deb8u5 which removed the inner class PrivilegedIntrospectHelper. This issue was fixed upstream [1] but the extra commit [2] wasn't documented on the Tomcat 7 security page [3]. The

Bug#846298: tomcat7: Security update causes java.lang.ClassNotFoundException: org.apache.jasper.runtime.JspRuntimeLibrary$PrivilegedIntrospectHelper

2016-11-29 Thread Anthony DeRobertis
Package: tomcat7 Version: 7.0.56-3+deb8u5 Severity: important I applied the latest security update and it broke tomcat completely. The logs show: SEVERE: SecurityClassLoad java.lang.ClassNotFoundException: org.apache.jasper.runtime.JspRuntimeLibrary$PrivilegedIntrospectHelper at